/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers: flaws in Bumble exposed info of ~95M Bumble users, including Facebook data of some, and it took over 200 days after being notified to fix the bug

Thomas Brewster / Forbes :

Forbes Thomas Brewster

Context & Ripple Effects

This story sits in a run of researcher-disclosed API and web bugs hitting consumer apps: Forbes' Thomas Brewster reports flaws in Bumble exposed data of roughly 95M users — including some Facebook-linked data — and that Bumble took over 200 days after notification to close the hole. The remediation clock is the story: when a comparable bug in fertility app Glow's forum exposed ~25M users' data, fixing it took about a week.

The Facebook angle echoes a familiar pattern. Researchers later documented that Facebook had known for years about contact-importer exploits that enabled scraping at 533M-user scale, and its 2018 breach left 50M accounts vulnerable to takeover. Bumble drawing on Facebook data means its exposure surface partly inherits the platform's.

First-order effects

  • Data of ~95M Bumble users was exposed while the bug stayed open for over 200 days after researchers flagged it, putting Bumble's security response process — not just the flaw itself — in question.

Second-order effects

  • Every dating app built on social-graph imports now faces the same researcher playbook, and Baidu's separately reported leak of sensitive user data in apps with ~1.4B downloads shows the audit wave is not platform-specific.

Third-order effects

  • If disclosure-to-fix time becomes the metric researchers and press rank vendors on — a week versus 200 days — slow responders will face structural pressure to adopt fixed remediation windows, and regulators get a ready-made yardstick for negligence claims.

The trend: Independent researchers are turning consumer-app API flaws into a recurring accountability beat where speed of remediation, not mere exposure, separates the defended from the negligent.

Discussion

  • @iblametom Thomas Brewster on x
    New - interesting tale of two vulnerability disclosures here. Bumble v. Hinge. https://www.forbes.com/...